Ransomware: What Every Organisation Should Do in
the First 24 Hours
The Day Everything Stops
It begins with what appears to be
an ordinary working day.
Employees arrive at the office,
switch on their computers and prepare for another day of business. Within
minutes, the first calls start coming through. Shared drives cannot be
accessed. Critical business applications fail to load. Customer records have disappeared,
accounting systems are unavailable and emails begin flooding the IT department
reporting the same problem.
Then the message appears.
Your files have been
encrypted.
To recover your data, follow
the payment instructions below.
In an instant, normal business
operations grind to a halt.
For many organisations, the
immediate reaction is panic. Questions arise faster than answers. Has customer
information been compromised? Should the ransom be paid? Who needs to be
informed? Can the business continue operating? Is this simply an information
technology incident, or has it become a full-scale organisational crisis? What
are the potential regulatory risks and penalties for POPPI breaches?
These are not decisions that can
be deferred until tomorrow. The first 24 hours following a ransomware attack
are often the most critical. The actions taken—or not taken—during this period
can significantly influence the extent of financial losses, operational
disruption, legal exposure and the organisation's ability to recover.
Ransomware is no longer simply a
cybersecurity issue. It is a business resilience challenge that demands
decisive leadership, coordinated incident response and disciplined
decision-making. Organisations that respond methodically are far more likely to
contain the damage, preserve critical evidence and restore operations than
those that react impulsively under pressure.
The true measure of resilience is
not whether an organisation experiences a cyberattack—it is how effectively it
responds when the attack occurs.
The First 24 Hours Matter Most
When ransomware strikes, every minute feels critical. The
instinct to restore systems immediately, negotiate with the attackers or simply
"fix the problem" is understandable. However, decisions made in haste
can unintentionally worsen the situation, destroy valuable forensic evidence or
prolong the organisation's recovery.
The first priority is containment. Affected systems
should be isolated from the network as quickly as possible to limit the spread
of the malware. At the same time, organisations should activate their incident
response plan, assemble the appropriate internal stakeholders and establish
a coordinated approach to managing the crisis. Ransomware is rarely confined to
the IT department—it quickly becomes an operational, legal, financial and
reputational issue that requires executive oversight.
Equally important is preserving evidence. While restoring
systems may seem like the logical first step, understanding how the attackers
gained access is critical to preventing a second compromise. Log files,
affected devices and system images may provide investigators with valuable
evidence regarding the attack vector, the scope of the compromise and whether
sensitive information was accessed or exfiltrated before encryption occurred.
Communication also plays a vital role during the early
stages of an incident. Employees require clear guidance on what has happened,
what actions they should avoid and how business operations will continue while
systems are being restored. Where customers, regulators or other stakeholders
may be affected, organisations should ensure that communications are accurate,
timely and coordinated. Poor communication can damage confidence just as
quickly as the cyberattack itself.
The first 24 hours are not about making every decision—they
are about making the right decisions. Organisations that remain calm, follow
established incident response procedures and preserve evidence are far better
positioned to contain the attack, support forensic investigations and recover
with confidence
Lessons from a Global Ransomware Attack
In February 2024, one of the world's largest healthcare
technology providers, Change Healthcare, suffered a ransomware
attack that disrupted healthcare services across the United States. Pharmacies
experienced delays in processing prescriptions, healthcare providers struggled
to submit insurance claims, and millions of patients were affected as critical
systems became unavailable. The incident demonstrated how a single cyberattack
could rapidly escalate into a nationwide operational crisis affecting
organisations far beyond the original victim. (UnitedHealth Group, 2024; CISA,
2024).
Investigations revealed that the attack had consequences
extending well beyond encrypted systems. Business operations were
interrupted for weeks, recovery costs escalated significantly, and the
organisation faced regulatory scrutiny, legal challenges and reputational
damage. Reports later indicated that the attackers had also exfiltrated
sensitive data before deploying the ransomware, highlighting that modern
ransomware attacks are increasingly driven by both operational disruption and
data extortion. (UnitedHealth Group, 2024; Reuters, 2024).
The Change Healthcare incident reinforces an important
lesson for every organisation: ransomware is no longer simply about restoring
encrypted files. It is about protecting business continuity, preserving
stakeholder confidence and ensuring that critical services can continue during
a crisis. Organisations that focus solely on recovering their systems often
overlook the broader governance, legal and operational challenges that follow a
significant cyber incident.
South Africa has experienced its own reminders of how cyber
incidents can disrupt critical services and expose organisations to significant
operational and information-security risks. In June 2024, the National Health
Laboratory Service (NHLS), which provides diagnostic pathology services to the
public healthcare sector, suffered a ransomware attack that rendered parts of
its information technology environment inaccessible and disrupted the
electronic communication of laboratory results to healthcare facilities. The
NHLS activated its incident response team while laboratories continued
processing clinical samples and urgent results were communicated telephonically
South Africa's financial and credit ecosystem has faced
different but equally instructive data-security incidents. In 2020, credit
bureau Experian experienced a fraudulent data incident that the Information
Regulator subsequently reported had exposed some personal information relating
to as many as 24 million South Africans and 793,749 business entities. The
Regulator's investigation found that the incident arose after Experian entered
into a commercial engagement with an individual misrepresenting themselves as a
director of a legitimate company
Although these incidents differ in method and impact, they
reinforce a common lesson: organisations responsible for critical services and
large volumes of personal information require effective incident-response
arrangements, strong information governance and tested business-continuity
measures.
For executives and boards, the lesson is clear. An effective
response cannot begin when the ransom note appears. It starts long before an
attack occurs through incident response planning, tested business continuity
arrangements, regular backups, executive decision-making protocols and clearly
defined communication strategies. The organisations that recover most
effectively are rarely those with the best technology alone—they are those that
have prepared for the possibility that technology may fail.
Cyber Resilience Begins Before the Attack
Ransomware is often described as a cybersecurity incident,
but its consequences extend far beyond information technology. It can disrupt
operations, interrupt customer services, expose sensitive information and place
significant financial, legal and reputational pressure on an organisation.
Responding effectively therefore requires far more than technical expertise—it
requires leadership, preparation and coordinated decision-making.
Cyber resilience is built long before an attack occurs.
Organisations should maintain tested incident response and business continuity
plans, perform regular offline backups, clearly define roles and
responsibilities during a cyber incident, and ensure employees understand how
to recognise and report suspicious activity. Equally important is preserving
digital evidence and understanding how the attack occurred before restoring
affected systems, reducing the likelihood of a repeat compromise.
No organisation can guarantee that it will never experience
a ransomware attack. However, every organisation can decide how well prepared
it will be when one occurs. The difference between a temporary disruption and a
prolonged business crisis is often determined long before the first system is
encrypted.
D-finitive Insight
Ransomware is no longer simply an information technology
issue—it is a business resilience challenge requiring coordinated leadership
across governance, risk management, information security, legal, operations and
executive management.
At D-finitive Advisory, our experience has consistently
shown that organisations recover more effectively when cyber resilience forms
part of their broader governance framework rather than being viewed solely as a
technical responsibility. Effective preparation combines strong governance,
clearly defined incident response procedures, tested business continuity
arrangements, digital forensic readiness and informed decision-making at every
level of the organisation.
The organisations that emerge strongest from a cyber
incident are rarely those with the largest technology budgets. They are the
organisations that prepare, respond decisively and continuously strengthen
their resilience against future threats.
Delivering Clarity. Protecting
Integrity. Driving Accountability.
